找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2248|回复: 0
打印 上一主题 下一主题

最新FCKEditor ASP上传绕过漏洞

[复制链接]
跳转到指定楼层
楼主
发表于 2012-12-10 10:18:50 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
exploiut-db:; b. Q! N, ^  l" p4 ?# T( u( g

+ D6 n1 L- I$ g3 m7 m( ?8 ZFCKEditor ASP Version 2.6.8 File Upload Protection Bypass
4 q4 f3 ^, K6 B1 d9 G. l2 |/ T1 t0 K# A
- Title: FCKEditor 2.6.8 ASP Version File Upload Protection bypass2 T. f) ]5 ~+ t% }0 G
- Credit goes to: Mostafa Azizi, Soroush Dalili
5 y5 r0 h2 R6 i9 W+ u- Link:http://sourceforge.net/projects/fckeditor/files/FCKeditor/6 {3 i8 W- ^6 l% ^
- Description:& [: T7 }/ {( S8 h/ d
There is no validation on the extensions when FCKEditor 2.6.8 ASP version is" |4 q8 S9 m9 j# a* h/ |
dealing with the duplicate files. As a result, it is possible to bypass
( n* Q) I" j+ N% C6 P  sthe protection and upload a file with any extension.
0 Y- A# ^' `2 N# q$ A8 \1 U. K- Reference: http://soroush.secproject.com/blog/2012/11/file-in-the-hole/  m0 S5 e5 l* Q* V5 r0 \7 C8 a- q+ `/ D
- Solution: Please check the provided reference or the vendor website." @- z+ X( |- X2 {
- PoC:http://www.youtube.com/v/1VpxlJ5 ... ;rel=0&vq=hd7204 i* g& s! l* e9 w' V
"
. U$ C* Q* E( @. ?- V$ LNote: Quick patch for FCKEditor 2.6.8 File Upload Bypass:
3 }% I$ }9 y7 F. X4 bIn “config.asp”, wherever you have:
% h' `5 v+ T; T8 {+ h9 O. V      ConfigAllowedExtensions.Add    “File”,”Extensions Here”
9 F6 h% E# T8 }5 I  yChange it to:  S8 g/ B" v9 l5 c3 a9 E/ I
      ConfigAllowedExtensions.Add    “File”,”^(Extensions Here)$”
# I" A4 a) J5 T* s) P
2 m. s4 i0 G6 g, `) c2 l9 O& w
2 r  O2 s. C4 u( N2 K8 P) h0 C1 w# B7 H9 {, x
: y$ v4 W) Z& f2 u% h( K7 u

: I5 P* t% _" S7 B  C6 Y% d/ @1 r! Yphp测试无效
6 x1 l6 M, P; _  Lasp/aspx测试成功:9 a% P+ c% l0 L0 A
来到/FCKeditor/editor/filemanager/connectors/test.html
) n9 p7 p: p( `1 F* _8 B6 p因为结合了之前二次上传的漏洞,所以先上传任意内容的文件:asd.asp.txt8 U- h. w4 d! I" N* a# O& _0 Z

+ B" f8 `) F8 O- x* `burpsuite上传包并修改,repeater( R2 f% a* A2 ]5 p; V) N
名字改为asd.asp%00txt    然后把%00专为URL编码上传后得到asd(1).asp
2 i% P  B9 g4 s5 \. r" a% d. W: q+ r* G& x* L( Y# }- J6 }
如图,webshell为:http://localhost/userfiles/file/asd(1).asp
3 m8 \( W. C+ R, {  N2 s, e- Y3 `( s8 o6 `
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表